The throughput number on the datasheet is measured with every inspection feature switched off. Turn them on and you are buying a different box.

A next-generation firewall inspects traffic at your edge: it identifies the application, decrypts what it is allowed to decrypt, matches it against threat signatures, logs it, and decides. Every one of those steps costs throughput, and the headline figure on the front page of the datasheet includes none of them.

Palo Alto publishes 7.5–20 Gbps threat prevention across the PA-3400 series and states exactly what was enabled — App-ID, IPS, antivirus, anti-spyware, WildFire, DNS Security, file blocking and logging. Most vendors lead with a raw firewall figure several times higher.

Already decided — before the sizing call

Your real traffic mixhow much is TLS, and must it be decrypted
Site count and shapeone data centre, or forty branches
The refresh windowand whether SASE lands inside it

Still yours to weigh

Throughputinspected, never raw
The subscriptionusually larger than the appliance
Managementincluded, or another product
If you’ve never bought one

What a next-generation firewall actually is

A device — physical, virtual or cloud — that sits where your network meets everything else and decides what may pass. The “next-generation” part means it identifies the application rather than just the port, can decrypt and inspect TLS, matches traffic against threat intelligence, and enforces policy per user rather than per IP address. Around that core, vendors add SD-WAN for connecting sites, sandboxing, DNS security and web filtering — usually as subscriptions.

Two numbers decide the purchase and only one is printed large. Inspected throughput — what the box does with threat prevention and logging enabled — and TLS inspection throughput, which is lower again and matters because most traffic is encrypted. Everything else is the commercial shape: what is in the subscription bundle, what management costs, and what happens at renewal. When enforcement should follow users off your network instead, that is the SASE & SSE guide.

The most common mis-purchase

Sizing on the datasheet’s headline figure and hitting a wall at a fraction of it once TLS inspection is on. Ask for the threat-prevention-enabled number, then ask for the TLS-inspection number, then add headroom for three years of traffic growth.

Often confused withSASE & SSE — enforcement in a provider's cloud instead of your edge·Zero Trust Access — replacing the VPN that terminates on this firewall·Secure Web & DNS — the cheapest control, deployed in front of everything

The four routes of network security — and which one is yours

Boundary — the terms this buyer confuses

NGFW vs UTM vs firewall · SD-WAN vs MPLS vs SASE

Two pairs this buyer confuses. Neither is a maturity ladder — each term describes a different scope or a different enforcement location, with different failure modes and different cost behaviour.

Firewall vs NGFW

A classic firewall allows or blocks by port, protocol and address — it knows nothing about what the traffic is. An NGFW identifies the application regardless of port, ties policy to user identity, decrypts TLS and matches against threat intelligence. The name is a generation, not a tier: nobody sells the classic kind for a perimeter any more, but plenty of internal segmentation still runs on it.

UTM vs NGFW

Unified threat management bundles many functions — firewall, antivirus, web filtering, mail filtering, VPN — into one box for a small estate that cannot run five. NGFW is about deep application inspection at scale. The engineering overlaps almost entirely today; the difference is where the vendor points the product. A UTM box asked to do enterprise inspection is where sizing disasters happen.

SD-WAN vs MPLS

MPLS is a carrier circuit with guaranteed behaviour and a long contract. SD-WAN is software that steers traffic across whatever links you have — broadband, 4G, MPLS — choosing per application and healing around problems. SD-WAN replaces the expensive circuit, not the inspection; you still decide where inspection happens, which is the next card.

SD-WAN vs SASE

SD-WAN connects sites and steers traffic; SASE moves the security enforcement itself into a provider's cloud so it applies wherever the user is. SASE is not 'firewall, evolved' — it is a different enforcement location with different failure modes (PoP latency instead of appliance capacity), different cost behaviour (subscription instead of refresh), and a different renewal trap. Many buyers need SD-WAN and no SASE; many need SASE and no SD-WAN.

These are not a maturity ladder. An estate with heavy site-to-site traffic and regulated inspection requirements may be correct to buy appliances for another decade; an estate whose people and applications have all left the building may be correct to buy no appliance at all. The expensive middle is owning both without reconciling what overlaps — which the category page opens with.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Seven variables decide this purchase. The instrument tests what documentation establishes (published inspected and TLS figures, form factor, SD-WAN, management, the vendor’s own SASE, India presence); real-world sizing, renewal behaviour and RMA turnaround are prose because the honest answers come from a proof of concept and a delivery team.

01

Real throughput with threat prevention, TLS inspection and logging enabled

The single most misleading spec in enterprise networking. Use the vendor's own inspected figure, note what was enabled when it was measured, and never accept the headline number.

02

TLS / SSL inspection performance

Most traffic is encrypted and decryption is the expensive part. A box sized on threat-prevention throughput can still fall over here — and the certificate rollout is a project of its own.

03

Form factor and HA model

Appliance, virtual, scale-out or cloud; active-passive or active-active. Scale-out (Maestro) changes how you grow — you add members rather than replace the box.

04

SD-WAN integrated or separate

In the licence (Fortinet, Versa), a separate product from the same vendor (Check Point, Cisco), or absent. It decides whether branch connectivity is one purchase or two.

05

Centralised management across sites

Included (Check Point, Versa, Sophos Central) or a separate product to licence and run (Panorama, FortiManager, Firewall Management Center). At ten sites it is a convenience; at a hundred it is the product.

06

Subscription bundling and renewal

Which features are in the bundle, which are add-ons, and what the same bundle costs in year four. Over five years the subscription usually exceeds the hardware.

07

Refresh cycle and the SASE question

A five-year appliance bought eighteen months before a SASE decision strands most of its value. Every vendor here except Sophos NDR sells its own SASE — negotiate the migration path before you sign, not after.

The narrowing instrument · the reasoning is the product

Narrow 12 products to your shortlist

Set what is true for you. A product that misses a constraint fades with its reason printed on it; where a vendor publishes no headline inspected figure it is flagged and stays, never eliminated on a number nobody published. Every chip is reversible.

Form factor

How you will size it

The network half

Management

The SASE question

India

Estate size

Real-world sizing, renewal behaviour and RMA turnaround are in the notes below rather than chips — the first needs your traffic mix, and the other two need a delivery team’s scar tissue.

Still in12/ 12
Fortinet logo
Appliance + bundle

appliance capex plus a UTP or Enterprise subscription bundle per year; the ASIC design is why the inspected figure holds up better than software-only rivals at the same price

Estates that want the best inspected throughput per rupee, SD-WAN in the same box, and a single vendor from branch to data centre to SASE.

The catch: The value comes from buying into the Fabric — FortiManager and FortiAnalyzer are separate purchases, and the subscription bundle you need (UTP vs Enterprise) changes the five-year cost more than the appliance does. Feature depth in the console lags the marketing.

ASIC-acceleratedSD-WAN integratedFabric add-ons
Intel page →
Fortinet logo
In the FortiGate licence

no separate SD-WAN licence — it runs on the FortiGate you already bought, which is the commercial argument; FortiManager for orchestration is separate

Multi-site estates that want application-steering, link remediation and security in one box rather than an overlay bought from someone else.

The catch: SD-WAN throughput with inspection enabled is not published as a separate figure — size from the FortiGate model's threat-protection number, not from an SD-WAN claim. Orchestration at scale needs FortiManager.

No separate licenceNeeds FortiManager at scaleInspected SD-WAN figure: not published
Intel page →
Palo Alto Networks logo
Appliance + CDSS

appliance capex plus Cloud-Delivered Security Services subscriptions per year; Panorama for central management is separate; Mumbai cloud location documented since 2021

Enterprises that want the deepest application identification and the most honest datasheet — Palo Alto states exactly which engines were enabled when the throughput was measured.

The catch: The premium option on both licence and subscription: CDSS bundles are where the five-year cost sits, and Panorama is another line. The full value assumes you adopt the platform rather than one appliance.

Transparent measurementCDSS subscriptionsPremium price
Intel page →
Check Point logo
Appliance + subscription

appliance capex plus a threat-prevention subscription; SmartConsole management is included rather than a separate product, which changes the comparison against Palo Alto and Fortinet

Security-first estates that want the strongest prevention posture and a management console included in the price rather than sold beside it.

The catch: SD-WAN is a separate product (Quantum SD-WAN), not a mode of the firewall; the appliance range is wide and model selection is unforgiving — the 9100's inspected figure is a fraction of the 29200's at a fraction of the price.

Management includedPrevention-firstSD-WAN separate
Intel page →
Check Point logo
Orchestrator + gateways

a hyperscale orchestrator that binds many gateways into one logical firewall — you buy the orchestrator plus the appliances it scales; throughput is the sum of the members, not a published single figure

Data centres that would otherwise buy a chassis: scale by adding gateways instead of replacing the box, with one policy across all of them.

The catch: No single inspected throughput figure exists for a scale-out cluster — it depends entirely on the member appliances, so size the members, not the orchestrator. It solves scaling, not the per-appliance inspection cost.

Scale-out, not a boxInspected figure: not applicableData-centre scale
Intel page →
Check Point logo
Subscription

a software blade on Quantum gateways rather than a separate appliance; application steering and link selection with Check Point inspection in path

Check Point estates adding branch connectivity without introducing a second vendor's overlay.

The catch: Newer than Fortinet's or Versa's SD-WAN and documented at smaller scale; no separate inspected throughput figure is published, so size from the underlying gateway.

On Quantum gatewaysYounger productSize from the gateway
Intel page →
Cisco logo
Appliance + subscription

appliance capex plus threat-defence subscriptions; Firewall Management Center is a separate deployment; the natural choice where Cisco already owns the network layer

Cisco-centric networks that want the firewall, the switching and the routing under one support contract and one account team.

The catch: Model-by-model inspected throughput figures vary widely across the 1000, 3100 and 4200 series and are not summarised here — pull the figure for your exact model from the datasheet and confirm which engines were enabled. Management is a separate deployment to run.

Cisco estate fitInspected figure: per modelSeparate management
Intel page →
Sophos logo
Appliance + protection bundle

appliance capex plus a Standard or Xstream Protection bundle; Sophos Central management is cloud-hosted and included, and the firewall shares signal with the Sophos endpoint agent

Mid-market estates — especially those already running Intercept X — that want firewall and endpoint sharing telemetry from one cloud console.

The catch: XGS models publish their inspection figures per model rather than as a headline series number; pull yours from the datasheet. Documented deployments are mid-market rather than large-enterprise, and the security heartbeat's value depends on running Sophos endpoints too.

Endpoint-firewall signalCloud console includedMid-market scale
Intel page →
Sophos logo
Per sensor

per deployed sensor, on quote; watches east-west traffic for anomalies and feeds Sophos XDR — it detects, it does not enforce

Estates that need to see lateral movement inside the network, where a perimeter firewall has no visibility at all.

The catch: Detection only: no inspection throughput figure applies because it blocks nothing. It is an addition to a firewall, never a replacement, and its value is realised through Sophos XDR or MDR.

Detection, not enforcementEast-west visibilityNeeds XDR/MDR
Intel page →
Barracuda logo
Per site / per user

SecureEdge is licensed per site for the firewall and per user for the access side, with bundled bandwidth; the same platform spans appliance, virtual and cloud-delivered enforcement

Distributed mid-market estates — retail, manufacturing, many small sites — that want one platform for branch firewalls and remote access without an enterprise project.

The catch: Inspected throughput figures are published per appliance model rather than as a series headline; documented deployments are mid-market. The per-site plus per-user split makes quotes hard to compare against per-appliance rivals.

Per site + per userMany small sitesMid-market
Intel page →
Versa Networks logo
Versa NGFWVersa Networks
Subscription

software-first, licensed by subscription on your hardware or Versa's; the same code runs the branch, the data centre and the SASE PoP, which is the architectural argument

Estates that want one software stack for SD-WAN, firewall and SASE rather than an appliance vendor's cloud service bolted on later.

The catch: Software-defined throughput depends on the hardware you run it on, so no single inspected figure applies — benchmark on your own platform. Smaller channel and support footprint in India than Fortinet or Palo Alto.

Software-firstOne stack to SASEBenchmark yourself
Intel page →
Versa Networks logo
Versa Secure SD-WANVersa Networks
Per site subscription

per branch site per year, with security services layered on the same instance; frequently sold through carriers as a managed service in India

Multi-site networks replacing MPLS that want routing, steering and inspection converged in software they can also run in the cloud later.

The catch: Often reached through a carrier's managed service rather than bought directly, which changes who holds the support relationship. No standalone inspected throughput figure — it is a function of your platform.

MPLS replacementOften carrier-managedSoftware throughput
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

Physical applianceRules out Check Point Quantum Maestro — software or scale-out only, no physical appliance form. That leaves Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos Firewall (XGS), Sophos NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN.

Virtual formRules out Check Point Quantum Maestro — no virtual form documented. That leaves Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos Firewall (XGS), Sophos NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN.

Scale-out capacityRules out Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos Firewall (XGS), Sophos NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN — capacity is bounded by the appliance model; growing means a bigger box. That leaves Check Point Quantum Maestro.

A published inspected figureRules nothing out on published terms. It flags Fortinet Secure SD-WAN — No headline inspected figure published for this product, Check Point Quantum Maestro — No headline inspected figure published for this product, Check Point Quantum SD-WAN — No headline inspected figure published for this product, Cisco Secure Firewall (Firepower) — No headline inspected figure published for this product, Sophos Firewall (XGS) — No headline inspected figure published for this product, Sophos NDR — No headline inspected figure published for this product, Barracuda Network Protection (SecureEdge) — No headline inspected figure published for this product, Versa NGFW — No headline inspected figure published for this product and Versa Secure SD-WAN — No headline inspected figure published for this product — marked on the cards, not removed.

A published TLS figureRules out Fortinet Secure SD-WAN, Check Point Quantum Maestro, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN — no TLS inspection throughput figure published; encrypted traffic performance is unproven on paper. That leaves Fortinet FortiGate (FortiOS), Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force and Sophos Firewall (XGS).

SD-WAN integratedRules out Check Point Quantum Force and Cisco Secure Firewall (Firepower) — SD-WAN is a separate product from the same vendor; Check Point Quantum Maestro and Sophos NDR — no SD-WAN capability. That leaves Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum SD-WAN, Sophos Firewall (XGS), Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN.

Management includedRules out Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series) and Cisco Secure Firewall (Firepower) — central management is a separate product to licence and deploy. That leaves Check Point Quantum Force, Check Point Quantum Maestro, Check Point Quantum SD-WAN, Sophos Firewall (XGS), Sophos NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN.

The vendor's own SASERules out Sophos NDR — no SASE platform from this vendor; a move means a second vendor and a parallel estate. That leaves Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum Maestro, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos Firewall (XGS), Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN.

India support presenceRules nothing out on published terms. It flags Fortinet FortiGate (FortiOS) — India support reaches you through the channel rather than a documented in-country vendor operation, Fortinet Secure SD-WAN — India support reaches you through the channel rather than a documented in-country vendor operation, Check Point Quantum Force — India support reaches you through the channel rather than a documented in-country vendor operation, Check Point Quantum Maestro — India support reaches you through the channel rather than a documented in-country vendor operation, Check Point Quantum SD-WAN — India support reaches you through the channel rather than a documented in-country vendor operation, Sophos Firewall (XGS) — India support reaches you through the channel rather than a documented in-country vendor operation, Sophos NDR — India support reaches you through the channel rather than a documented in-country vendor operation, Barracuda Network Protection (SecureEdge) — India support reaches you through the channel rather than a documented in-country vendor operation, Versa NGFW — India support reaches you through the channel rather than a documented in-country vendor operation and Versa Secure SD-WAN — India support reaches you through the channel rather than a documented in-country vendor operation — marked on the cards, not removed.

Data-centre scaleRules nothing out on published terms. It flags Check Point Quantum SD-WAN — Unverified at data-centre scale, Sophos Firewall (XGS) — Unverified at data-centre scale, Sophos NDR — Unverified at data-centre scale and Barracuda Network Protection (SecureEdge) — Unverified at data-centre scale — marked on the cards, not removed.

The only throughput number worth readingEvery firewall datasheet leads with a raw firewall figure measured with inspection switched off. It tells you nothing about the box you will actually run. The figures on this page are the vendors' own threat-prevention-enabled numbers, and where a vendor publishes one it is stated with what was enabled: Palo Alto's PA-3400 series at 7.5–20 Gbps is measured with App-ID, IPS, antivirus, anti-spyware, WildFire, DNS Security, file blocking and logging on; Fortinet's 100F at 1.6 Gbps threat protection; Check Point's Force 9100 at 6.5 Gbps rising to 75 Gbps on the 29200. Where no headline inspected figure is published — Cisco, Sophos and Barracuda publish per model, Versa is software, Maestro is scale-out, Sophos NDR blocks nothing — it is marked and not derived. Never size from a raw figure, and never let a reseller do it either.

TLS inspection is where appliances actually fall overMost traffic is encrypted, and decryption is far more expensive than inspection. A box sized on threat-prevention throughput can still collapse when TLS inspection is switched on for real traffic. Palo Alto, Fortinet, Check Point and Sophos publish TLS or SSL inspection figures; the rest on this page do not — flagged, not ruled out. Ask for the figure with your own cipher mix, and plan the certificate deployment before the purchase order.

The subscription is the bigger numberOver five years the security subscription usually exceeds the appliance it runs on, and the renewal is where the surprise lives. Read which features are in the bundle you are quoted (Fortinet UTP vs Enterprise, Palo Alto's CDSS set, Check Point's threat-prevention package, Sophos Standard vs Xstream) and what the same bundle costs in year four. Central management — Panorama, FortiManager, Firewall Management Center — is a separate line at three of these vendors and included at two.

Refresh cycles and the SASE decisionAn appliance bought today is a five-year commitment; a SASE decision taken eighteen months from now strands most of it. Every vendor here except Sophos NDR sells its own SASE, which makes a phased move commercially easier — but it does not make the appliance's remaining book value disappear. If a SASE evaluation is plausible within the refresh window, size shorter or negotiate a migration path into the contract now.

India support and RMAPalo Alto and Cisco document in-country operations; the rest reach you through the channel, which is not worse but is different — the RMA clock, the spares depot and the escalation path belong to your partner, not the vendor. Real RMA turnaround by vendor and city is delivery-team knowledge: [TechBag to confirm].

Narrow to your situation

Eight situations, eight shortlists — with the sizing named

Each shortlist states how you would size it and what the subscription does to the five-year number. If a SASE decision is plausible in your refresh window, start from the fourth row.

Branch and mid-size sites, best inspected throughput per rupee

Why: FortiGate's ASIC design keeps the threat-protection figure high relative to price and includes SD-WAN; Sophos and Barracuda target the same band with cloud management included.

The trade-off: Fortinet's value assumes buying into the Fabric (FortiManager, FortiAnalyzer); Sophos and Barracuda are documented at mid-market rather than data-centre scale.

Data centre, above 10 Gbps with inspection on

Why: Palo Alto's PA-3400 series publishes 7.5–20 Gbps threat prevention with every engine named; Check Point's Force line reaches 35–75 Gbps inspected on the 19100 and 29200; Maestro scales by adding gateways instead of replacing the chassis.

The trade-off: Maestro has no single inspected figure — it is the sum of its members, so the sizing work moves to the member appliances rather than disappearing.

Replacing MPLS across many sites

Why: Versa is software-first and often delivered as a carrier-managed service in India; Fortinet includes SD-WAN in the FortiGate licence with no separate SKU; Check Point runs it as a blade on Quantum gateways.

The trade-off: None of the three publishes a separate inspected SD-WAN throughput figure — size from the underlying platform. Carrier-managed delivery changes who owns your support relationship.

A SASE decision is likely within the refresh window

Why: All three vendors sell their own SASE, so the appliance and the future cloud enforcement come from one contract and one policy model — Versa most literally, since the same software runs both.

The trade-off: Same-vendor continuity does not recover the appliance's book value. Negotiate the migration terms into the appliance contract now, while you still have leverage.

Cisco already owns the network layer

Why: One support contract and one account team across switching, routing and firewall is a real operational argument; the alternatives win on published inspection transparency.

The trade-off: Cisco's inspected figures must be pulled per model rather than read off a series headline, and Firewall Management Center is a separate deployment to run.

The firewall should share signal with the endpoint

Why: Sophos Firewall and Intercept X exchange a security heartbeat from one cloud console; Fortinet does the equivalent through the Fabric; Sophos NDR adds east-west visibility a perimeter firewall cannot have.

The trade-off: The heartbeat's value depends on running that vendor's endpoint too — a second lock-in. NDR detects and enforces nothing.

Management console included, not another product to buy and run

Why: Check Point includes SmartConsole management, Versa includes its director, and Sophos Central is cloud-hosted and included — against Panorama, FortiManager and Firewall Management Center as separate lines.

The trade-off: Included management is not always equivalent management: compare multi-site policy, role separation and reporting depth, not just the licence line.

Many small sites, one platform, no enterprise project

Why: Barracuda SecureEdge licenses per site for the firewall and per user for access on one platform; Sophos and Fortinet cover the same estate from cloud consoles.

The trade-off: Barracuda's split meter is hard to compare against per-appliance quotes — normalise to a per-site annual cost including the subscription before choosing.

The spine of the decision

Four throughput numbers, and only one of them is real

Every datasheet publishes a ladder of figures that fall as you enable the features you bought the box for. Read them in this order, and size on the last one you will actually run.

Figure 1

Raw firewall throughput

Packets forwarded with inspection off. The number on the front page, the number in the reseller's email, and the number that describes no box anyone deploys. Useful only for comparing interface capacity.

Figure 2

IPS or application-control throughput

One engine enabled. Better, still not your configuration — nobody buys a next-generation firewall to run one engine.

Figure 3

Threat prevention enabled

The engines you actually paid for, running together, with logging on. This is the figure to size against. Palo Alto's PA-3400 series: 7.5–20 Gbps with threat prevention enabled. Fortinet 100F: 1.6 Gbps threat protection. Check Point Force 9100: 6.5 Gbps threat prevention, rising to 75 Gbps on the 29200.

Figure 4

TLS inspection enabled

Lower again, and the one most estates need because most traffic is encrypted. Published by Palo Alto, Fortinet, Check Point and Sophos; not published by the others here — flagged, not assumed.

The sizing test

Ask these before the quote, in this order.

  • What is the threat-prevention-enabled figure, and which engines were on? Palo Alto names all eight in its datasheet. If a vendor will not answer this precisely, you cannot size against them.
  • What is the TLS inspection figure with our cipher mix? Not the lab mix. And who deploys the certificates — because that is the project that stalls the rollout.
  • What does this bundle cost in year four? Over five years the subscription usually exceeds the appliance.
  • If we move to SASE in year three, what happens to this box? Ask before signing, while you still have leverage.

The three-line cost

An appliance purchase is never one number.

  • Capex — the appliance. Visible, negotiated hard, and usually the smallest of the three over five years. It also depreciates on a schedule that a SASE decision does not respect.
  • Opex — the subscription. Threat prevention, sandboxing, web filtering, DNS security. Bundled differently by every vendor (Fortinet UTP vs Enterprise, Palo Alto CDSS, Check Point threat prevention, Sophos Standard vs Xstream), and repriced at renewal.
  • Opex — support and management. Hardware support with an RMA commitment, plus central management as a separate product at Palo Alto, Fortinet and Cisco — included at Check Point, Versa and Sophos.
  • And the fourth line nobody quotes: the parallel run if SASE arrives mid-term. That is the double-spend the category page opens with.
What breaks as you grow

What changes at 1 Gbps, 10 Gbps and above

Firewalls scale by inspected throughput and by site count, and the two need different answers. The bill follows the appliance tier; the operational load follows the number of policies and consoles.

1 Gbpsinspected throughput

Sizing honesty is the constraint

  • A single branch or a small office: FortiGate, Sophos XGS and Barracuda all cover it, and the temptation is to size on the headline figure and buy one model too small.
  • TLS inspection may be the deciding factor even here — a 1.6 Gbps threat-protection box does not do 1.6 Gbps of decrypted traffic.
  • Cloud-managed consoles (Sophos Central, Barracuda) save an appliance's worth of operational effort.

Put this in your PoC

Run the proof of concept with TLS inspection on and your own traffic. If the vendor resists, that is the finding.

10 Gbpsinspected throughput

TLS and management are the constraint

  • Now the inspected figure is the whole conversation: Palo Alto's PA-3400 series and Check Point's Force line publish theirs; pull the exact model's number and add three years of growth.
  • Central management stops being optional — Panorama, FortiManager or Firewall Management Center is a separate product to licence, deploy and staff at three of these vendors.
  • The subscription bundle now dominates the five-year cost, and renewal terms deserve as much attention as the discount.

Put this in your PoC

Ask three vendors for their inspected and TLS figures on the exact models quoted, in writing, with the datasheet date. The spread will decide the shortlist.

Above 10 Gbpsinspected throughput

Architecture and the refresh horizon are the constraint

  • Scale-out (Check Point Maestro) versus a bigger chassis becomes a real architectural choice — Maestro has no single inspected figure because it is the sum of its members.
  • At this size a SASE evaluation is almost certainly already running somewhere in the organisation; buying a five-year appliance without reconciling the two is how the double-spend starts.
  • Sophos, Barracuda, Check Point SD-WAN and Versa's smaller deployments are flagged unverified at data-centre scale — not ruled out; ask for the reference.

Put this in your PoC

Model the five-year cost of appliances plus subscriptions against the same estate on SASE. If nobody has done that comparison, the refresh decision is being made blind.

Fortinet, Palo Alto, Check Point, Cisco and Versa document data-centre-scale deployments; Sophos Firewall, Sophos NDR, Barracuda Network Protection and Check Point Quantum SD-WAN are flagged unverified above 10 Gbps inspected. Where a specific product strains for your traffic profile: [TechBag to confirm].

The switching cost

Leaving a firewall estate is a policy migration, not a swap

The appliance is the easy part. The rule base — grown over years, full of exceptions nobody remembers — is what actually moves, and it rarely moves cleanly.

The rule base

Thousands of rules, many redundant, some load-bearing for an application nobody can name. Automated converters get most of the way; the last 10% is manual and is where outages come from.

Exit costConvert, then audit

Certificates and TLS

The decryption trust chain is per platform: new certificates deployed to every endpoint before the cut-over, or inspection silently stops working for someone.

Exit costRe-deploy before cut-over

The parallel run

Both estates live while sites cut over one at a time, which means two support contracts and two subscription bills for a quarter or more.

Exit costOverlap, site by site

The remaining book value

The appliance you are leaving is on a depreciation schedule that does not care about your architecture decision. Finance will ask; have the number before they do.

Exit costWrite-down or run-out

Rule-base conversion effort, certificate rollout and parallel-run cost for your estate: [TechBag to confirm] — TechBag scopes it from your rule count, site count and refresh dates.

What it costs

Three lines, and the subscription is usually the largest

What you may already hold, the appliance and subscription shape at three estate sizes, and what the licence line leaves out — which, for firewalls, starts with the box you are still paying for.

01

Do you already own one?

Four things that may already inspect part of this. Two of them genuinely do.

Your existing NGFW subscription
Often Web filtering, DNS security, application control and sometimes SD-WAN are frequently already in the bundle you renew each year — unused because nobody switched them on. Audit the bundle before buying the same capability again.
Your ISP or carrier's managed service
Partly Many Indian carriers deliver SD-WAN and basic security as a managed service, often on Versa or Fortinet. Real capability; ask who holds the policy and how fast a change request moves.
Cloud-native firewalls
Partly AWS Network Firewall, Azure Firewall and their equivalents protect traffic inside that cloud, on consumption. They do not reach your data centre or your branches.
Your endpoint vendor's network module
No Host firewalls and endpoint web filtering protect the device, not the segment. Useful, and not a substitute for inspection between networks.

If the capability you need is already inside a subscription you renew every year, we say so. It costs us a sale and saves you one.

02

What the rest actually cost

Firewall pricing is quoted, not listed — the honest thing to publish is the shape of the bill rather than invented per-unit numbers. Three lines at three estate sizes, with the vendors that publish per-user or per-site meters named explicitly, and the India-built and mid-market options covered because no global comparison does.

One site · ~1 Gbps inspected
  • Appliance (capex)A branch-class box — FortiGate 100-series, Sophos XGS desktop, Barracuda SecureEdge appliance. Amortised over five years.
  • Subscription (opex)The protection bundle, renewed annually. Frequently comparable to the appliance's annual amortisation.
  • Support + managementHardware support with an RMA commitment; cloud management included at Sophos and Barracuda.
Ten sites · ~10 Gbps inspected at the hub
  • Appliance (capex)A hub pair plus branch boxes. HA doubles the hub hardware; the branches multiply.
  • Subscription (opex)Per appliance, every year, across every site — now clearly the largest of the three lines over five years.
  • Support + managementCentral management becomes a separate product at Palo Alto, Fortinet and Cisco; included at Check Point, Versa and Sophos.
Data centre · above 10 Gbps inspected
  • Appliance (capex)Chassis or scale-out members (Maestro). Sized on the inspected figure for the exact model, plus growth headroom.
  • Subscription (opex)Enterprise bundles with the highest per-appliance cost; the renewal is a board-visible number.
  • Support + managementPremium support with a tighter RMA, a management cluster, and the people to run it.

The published meters — where they exist, and the mid-market and India options

Per user, per month. Where a vendor sells the access side as a service rather than a box: Barracuda SecureEdge Access, and the SASE products on the neighbouring guide. Comparable to a subscription, not to an appliance.
Per site, per year. Versa Secure SD-WAN and Barracuda SecureEdge licence this way, which suits many-small-sites estates and makes an appliance comparison awkward — normalise both to an annual cost per site including subscription.
The mid-market and India cut. Sophos, Barracuda and Fortinet dominate quotes in the Indian mid-market; Versa reaches many estates through carrier-managed services. All quote through the channel in INR with GST. TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes.
Tier-match: the bundle is the product. Fortinet UTP is not Enterprise; Sophos Standard is not Xstream; Palo Alto’s CDSS set is modular. Two quotes for “the same” firewall routinely contain different security services. Compare the enabled features, not the model number.
Term-match: five years, not one. Appliance capex amortises over five; subscriptions renew annually and reprice. A one-year comparison flatters the appliance and hides the renewal — model five years, with year four’s subscription quoted in writing.
The India line. Palo Alto and Cisco document in-country operations; everyone else supports through the channel, so the RMA clock and spares depot belong to your partner. Get the RMA commitment in the contract, by city.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

The appliance you are still paying for

If SASE arrives mid-refresh, the remaining book value does not disappear — and the parallel run is a real line for a quarter or more. This is the double-spend the category opens with, and it belongs in the business case before the purchase order.

Circuits, bandwidth and the certificate project

The links the firewall sits on, the bandwidth upgrade the inspection makes necessary, and the TLS certificate rollout to every endpoint — none of it is in the quote, all of it is in the timeline.

Rule-base and operational time

Policy migration, exception review, and the people to run the console day to day. A firewall with an unaudited rule base is an expensive router. Your hours: [TechBag to confirm].

Before you commit

What goes wrong

Documented behaviour and sizing outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover at the traffic peak.

Sizing on datasheet throughput and hitting a wall with TLS on

The headline figure was raw; the box met a fraction of it once decryption was enabled for real traffic. Size on the threat-prevention figure, then check the TLS figure.

Subscription renewals costing more than the hardware

The appliance was negotiated hard and the year-four renewal was not. Over five years the subscription is usually the larger number — get year four in writing at signature.

HA pairs that fail over but drop sessions

The cluster worked in the test and dropped long-lived sessions in production. Test failover with real application sessions, not pings.

RMA times that don't match the SLA in India

The contract said four hours; the spare was in another country. Confirm the depot, the city and the escalation path with your partner, in the contract.

Buying a five-year appliance eighteen months before a SASE decision

Two enforcement estates, overlapping capability, and a depreciation schedule that does not care. Reconcile the roadmap before the refresh, not after.

The bundle that didn't include the feature demonstrated

Sandboxing or DNS security was in the demo and not in the quoted tier. Compare enabled features, not model numbers.

Certificate deployment stalling the inspection rollout

TLS inspection was licensed, configured and never switched on because the certificates never reached the endpoints. It is a device-management project, and it belongs in the plan.

A rule base nobody audited

Years of accumulated exceptions, some load-bearing, most redundant. Migration exposed it, and the outage came from the 10% no converter could translate.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Network Security & SASE map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.